HIGH
CVE-2022-2185
CVSS
8.8
Description
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.
Summary dbcve.org
A vulnerability in GitLab's project import feature allows authenticated users with import permissions to import a maliciously crafted project that can execute arbitrary code on the GitLab server.
Mitigation
Upgrade GitLab to version 14.10.5, 15.0.4, 15.1.1 or later. Until patched, disable project import functionality for untrusted users.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
76.65%
Probability of exploitation in next 30 days
99.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.